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29 August 1979 


MEMORANDUM FOR: Deputy Director for Administration 

FROM: James H. McDonald 

Director of Logistics 

SUBJECT: Industrial Security Oversight 25X1 

REFERENCE: D/OS memo dtd 17 August 1979, same 

subject; (DDA 79-2725) 


1. I believe Bob has given a pretty good picture of his 
oversight into the industrial contract/security efforts of the 
Agency. There is certainly far more liaison and interface now 
with elements of the main Office of Security and Industrial 
Security Officers (ISO) assigned to Logistics or S$T than there 
was just a few years ago. These channels of communication are 
clear and, as Bob states, are fast and free of pr otoco l so that 

he or his staff is quickly informed of problems. | | 25X1 

2. As he points out in paragraph 6, however, the key in- 

gredient is the relationship created between the contractor and 
the ISO assigned to Logistics or S§T who works with the contrac- 
tor on a day-to-day basis. This relationship is further enhanced 
by the degree of rapport and understanding between the ISO and 
his contracting officer, since it is only through the latter that 
the contractor's compliance with security provisions is imple- 
mented and enforced. I believe these relationships are at an 

alltime high and we are all working very closely together. | | 25X1 

3. Where there is conflict between the contracting/security 
officers and the technical officers that cannot be resolved at 
the component level, Bob and I have jointly addressed these 
issues particularly with S§T. An example of such is the 

joint memorandum to the D/ORD/S§T on the issue of incorporating 
the new Industrial Security Manual (memorandum attached) . 

I 1 25X1 


OL 9-3613 

Vv/i 5 

Approved For Release 2003/02/27 : CIA-RDP82-00599R0001 001 70002-7 




^ i 

Approved For Rele^^)|[^/a2/ggj^l|Y?^|2-00599R0001 001 70002-7 


SUBJECT: Industrial Security Oversight 


4. I would take issue with Bob on only one point, and 
that is the use of security audit teams mentioned in para- 
graph 7. As Bob points out, these unannounced audits result 
in recommendations which are forwarded to Logistics or S§T for 
appropriate action. I am not so sure that it wouldn't be a 
better investment of resources to assign these security offi- 
cers now doing audits to the contracting elements/teams to 
work closely with contractors on a daily basis to develop good 
security practices and policies, as opposed to an annual, or 
at best a biennial, review. If something is wrong now, I 
don't think we should wait a year or two to find out. This 
type of resource investment is particularly applicable to the 
Logistics contracting program as opposed to the National 
programs. These types of industrial security programs are 
different, in that under the National programs security follows 
the particular contract or project and there is continuous 
contact and liaison between the security officers and the con- 
tractors. On the Agency, or Logistics, side it is more of an 
industrial facility security program. By this I mean the 
security procedures for a facility are established and approved 
to accept a variety of contracts from many different Agency 
components. At any given time there may be a dozen or more 
different contracts in a contractor’s facility, involving five 
or six different contracting elements/teams. Therefore, it is 
necessary that a consistent, and perhaps a broader, security 
policy framework be established for the contractor to work 
within since it is not possible for the ISO to monitor individual 
contracts on a daily basis. Additional resources would increase 

the amount of contact between OL, ISO’s, and contractors, pro- 

viding a more current examination of contractors’ practices. 
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j 5 AUG 19^9 


MEMORANDUM FOR: Director of Research and Development 


FROM: 


James H. McDonald 
Director of Logistics 


Robert W. Gambino 
Director of Security 


SUBJECT: 


Security Requirements | | 


25X1 


REFERENCE: 


D/R$D memo dtd 23 July 1979, subject 
Security Procedures for Contractors 
(ORD 1105-79) 


1. We have reviewed your comments in referent concerning 
our new industrial security manual , Standard Security Procedures 
for Contractors, and will address the various issues you have 
raised. Initially, however, we would like to clarify an appar- 
ent misunderstanding. The new industrial security manual is 
not in effect at the present time. It is currently being 
distributed to contractors, and will not become effective earlier 
than 120 days after receipt. Contractors are also afforded the 
opportunity to voice any concerns, request waivers, or submit 
proposal s for resultant cost increases by virtue of the new 
manual. | | 


2. The decision to purchase the security container for 
the I I was made under existing security 

regulations. While the new industrial security manual does 
strengthen some security areas, it does not significantly 
change current storage standards. Th e rpn uirement to alarm, 
for example, is not a new criterion. | 


25X1 


3. Your concern for the impact of the manual on small 
contractors is understandable and we share it. We perceive 
difficulty, however, in attempting to establish different 
security standards to accommodate the various strata of 
vendors who will contend for classified Agency contracts. 


25X1 
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25X1 


25X1 

25X1 


5. Obviously, there are always some inequities between 
contractors despite the attempts we make to equalize their 
opportunities to bid. In the past, our Agency Industrial 
Security Officers have always exhibited flexibility in find- 
ing solutions which will allow our procurement actions to 
proceed with minimal risk. The Agency Task Force on Indus- 
trial Contracts and Industrial Security reinforced this 
philosophy in their recommendation to the DCI , in response 
to his request for a new, uniform and precise industrial 
security manual,- by stating that "...we cannot completely 
abandon the flexibility which has permitted the experienced 
Industrial Security Officer to make reasoned, independent 
security judgments on-site consonant with cover and opera- 
tional considerations." Thus, when the situation demands, 
the Industrial Security Officer can, with approval from 25X1 

appropriate authorities and careful recording of the fact . 

make adjustments which will best serve Agency programs. | | 


6. In the instant case, while the [ | 

Company's safekeeping equipment technically did not meet 
security standards, the cognizant Industrial Security Officer, 
after an overall security assessment, decided to allow the 
contractor to continue on our contract. During the most 
recent security inspection, it was determined that the con- 
tractor's efforts no w involve such considerations as the 


25X 
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storage of sight- sensitive equipment and classified ADP discs 
in addition to classified documents. As a consequence, a 
technically approved security container was recommended. In 

view of the contractor's location, an alarm requirement was 

not levied by the cognizant Industrial Security Officer. | | 25X1 

7. In summary, we agree with your observations con- 
cerning the difficulties we face in bringing new contractors 
into the classified RFP arena and we will do everything 
consonant with good security to assure the flexibility 
necessary to promote maximum competitive opportunities. 


/s/ James H. McDonald? 

James H. McDonald 

Distribution : 

Orig - Adsee 

1 - D/Security 
1 - D/L Chrono 
- OL Official 
1 - OL/SS 
1 - OL/PMS 
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DD/A Registry 


17 AUG 1979 


MEMORANDUM FOR: 


FROM: 


SUBJECT: 


Deputy Director for Administration 

Robert W. Gambino 
Director of Security 

Industrial Security Oversight 


25X1 


1. Action Requested: None; for information only. □ 

2. In all classified contracting modes, it is recognized 

that security is a command responsibility and that security 
guidance must ultimately be provided to the contracting 
officer who alone possesses the delegation of authority to 
sign contracts binding the Government and, by contractu al 
agreement, establishes binding security requirements. | | 


25X1 


3. Agency regulations, as revised 
approval of an Industrial Security Task 
the Director of Security with coordinat 
trial security effort of the Agency; in 
security support is well organized and 
functional supervision over all Agency 
Officers; developing and publishing uni 
and standards for industrial contractua 
providing trained professional security 
Agency components engaged in industrial 


in 1978 following DCI, 
Force report, charge 
ing the entire indus- 
suring that industrial 
effective; exercising 
Industrial Security 
form security policy 
1 arrangements; and 
officers to t hose 
contracting. | | 


4. The terms used in th 
spell out the dichotomy which 
and National programs. The i 
the functional oversight to b 
Security extends over both ar 
continue was reaffirmed by th 
recommendation of the Industr 
Security Task Force to establ 


ese regulatory functions do not 
exists between Agency programs 
ntent is clear, however, that 
e provided by the Director of 
eas. (That the dichotomy would 
e decision to not approve the 
ial Contracts and Industrial 
ish a single delegation of 
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25X1 


25X1 


contracting authority rather than continuing the existing 
dual delegation from the DCI to the Director of Logistics 
and to the Chief, Contr acts Staff, Office of Development 
and Engineering.) | | 


5. In recognition of thi 
Director of Security exercises 
two senior career security off 
Staff, OD^E, and the Chief, Se 
seasoned professionals can be 
Director of Security promptly 
problems arising in the physic 
security areas; security decis 
policy variances; and security 
ence to security standards ere 
job done. The system is fast, 
and provides the Director of S 
to be aware of deviations , ma k 
reach timely decisions. | | 


s continuing dichotomy, the 
oversight primarily through 
icers -- the Chief, Security 
curity Staff, OL. These 
counted upon to inform the 
of any security flaps; 
al, technical, and personnel 
ions involving important 
decisions where rigid adher- 
ates a standoff in getting the 
flexible, free of protocol, 
ecurity with the opportunity 
e reasoned judgments, and 


25X1 


6. In order, however, for the Director of Security 
to achieve maximum oversight of the entire industrial secu- 
rity support system, the following additional steps have 
been taken to bring the Director of Security and the Indus- 
trial Security Officer closer together. (The Industrial 
Security Officer is an active participant in the classified 
contracting team concept. The more conversant he is with 
the technical aspects of his contracts, the more effective 
he can be in working up security plans and providing guidance. 
The relationships he creates with his contractors go a long 
way toward determining how much feedback and knowledge the 
contracting components and the Director of Security obtain 
regarding incipient or active security problems -- it must 
be a carefully nurtured, professional relationship, establish- 
ing a working rapport of mutual problem solving. Once 
established, this relationship fills an informational and 
timeliness need which no formal inspection system can ever 
provide . ) 


Approved For Release 200?/ l Q2/27-t CIA-I 

Cum*Iutri i lAL 


-RDP82-00599R0001 001 70002-7 


» ■» 

Approved For Releafee'i 


: C1A-RDP82-00599R0001 001 70002-7 


25X1 
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a. Letters of Instruction tailored for 

each individual Industrial Security Officer 
(ISO) have been prepared, reviewed a nd 
approved by the Office of Security. | | 

b. The fitness report for each ISO (which 

is written by the contracting component) is 
reviewed by the Office of Security. An overall 
evaluation as to each ISO's performance in 
carrying out security policy is prepared, 
reviewed with the officer, and formally re- 
corded in the official personnel file. | | 

9^ Each individual ISO (including those 

p is seen personally by a 

senior representative of the Office of Security 
on a one-on-one basis at a minimum of twice a 
year. A report of eac h mee ting is given to the 
Director of Security. J | 

d. Monthly activities reports from each 

contracting component are submi tted to the 
Office of Security for review. | | 

e. The Director of Security meets personally 

once a month with a croup which inrliMpg all 

ISO’ s 

in order to Keep them abreast of Office policy 
and activities. On a biweekly basis, the 
Director of Security meets with a group which 
includes the senior ISO from the staffs of the 
Director of Logistics and t he Director of Develop- 
ment and Engineering. | | 

f. A representative of the Director of Secu- 

rity attends the monthly meeti ng of all ISO's 
involved in Agency contracts. | | 

g. A representative of the Director of 
Security sits on the Agency Contract Review 
Board and the newly created National Programs 
Contract Review Board. I I 
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h. A direct link has been set up from 
each ISO to a senior representative of the 
Director of Security through which the ISO 
can express his formal written views of 
security audit findings and seek other solu- 
tions when phd-S-, prof ess ional judgment so 
25X1 di ctates. | | 

7. In order to assess the quality of the security 
support at contractor sites, the Industrial Security Branch 
conducts unannounced security audits, the results of which 
are forwarded to the Office of Development and Engineering 
and/or the Office of Logistics for appropriate action. To 
streamline the security auditing process. Office of Security 
auditors have recently adopted the practice of giving their 
recommendations directly to the cognizant ISO within 10 days 
after completing the audit. A senior representative of the 
Director o f Sec urity attends each one of these briefing 

25X1 sessions. | | 

8. In coordination with the Director of Logistics 
and the Dep uty Director for Science and Technology, the 

25X1 | ISO streng th has been increased from five to 

9EX1 nine with area management responsibilities 

placed clearly with one senior ISO for the National program 
and one senior ISO for the Agency program. The old anomaly 
of having the DDS§T provide security manage ment for non- 
DDS^T Agency programs has been eliminated. | | 

9. In coordination with the Director of Logistics, 
two additional ISO's have been assigned to the Security 
Staff of that Office to i ncrease contractor security over- 

25X1 sight capabilities. | | 

10. A new industrial security manual. Standard Security 

Procedures for Contractors, has been prepared and sent out 
to some - 400 contractor s~Tor their review and comments prior 
to incorporating its terms into existing a nd fu ture con- 
tracts. (A copy accompanies this paper.) | | 

11. A second industrial security seminar will be given 
this fall for some 40 contractors' security representatives. 
Included on the agenda will be discussions on improving 


25X1 
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communications, the impact of APEX on the SCI world, the FBI 
Industrial Counterintelligence program, the impact of the 
terms of the new industrial security manual, and finally 
individual discussions o n ite ms of particular interest to 
25X1 any of the contractors. | | 

12. The following table gives the location and number 
of the Industrial Security Officers currently serving outside 
the Office of Security in the Agency and National programs: 
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